The SCS-C03 exam
Format, domain weights, what changed from SCS-C02, and a method for security scenario questions.
Format
Where the points are
| Domain | Weight | In one sentence |
|---|---|---|
| 1 · Detection | 16% | Monitoring, alerting and logging across an account or organization, and fixing them when they break |
| 2 · Incident response | 14% | Designing and testing a response plan, then responding to real events |
| 3 · Infrastructure security | 18% | Edge services, compute workloads and network controls |
| 4 · Identity and access management | 20% | Authentication and authorization, and troubleshooting both |
| 5 · Data protection | 18% | Data in transit, data at rest, and the keys, secrets and credentials behind them |
| 6 · Security foundations and governance | 14% | Account structure, consistent deployment and compliance evaluation |
IAM is now the heaviest domain. Almost every question in other domains also has an IAM angle: the automation role
that needs kms:Decrypt, the log bucket policy that must trust a service principal, the SCP that blocks the fix.
What changed from SCS-C02
| Area | Change |
|---|---|
| Domains 1 and 2 | "Threat detection and incident response" and "Security logging and monitoring" became Detection and Incident response |
| Domain 6 | Renamed from "Management and security governance" to Security foundations and governance |
| Weights | IAM up from 16% to 20%. Infrastructure security down from 20% to 18%. Detection 16%, incident response 14% |
| New skills | Validating findings to assess scope and impact, OCSF and third-party WAF rules, guardrails for generative AI, inter-node encryption in transit, imported vs AWS generated key material, masking sensitive data, keys and certificates across Regions |
| Removed | ASFF details, host-based firewalls, basic TCP/IP and TLS concepts, policy element basics, S3 static website hosting |
How to read a security question
| Phrase in the question | What it points to |
|---|---|
| Least privilege | Narrow actions and resources, conditions on the policy. Rules out * and broad managed policies |
| Across all accounts / the organization | Delegated administrator, organization trails, SCPs and RCPs, Firewall Manager, StackSets |
| Least operational overhead | Managed detections and managed rules over custom Lambda functions and agents |
| Must not be able to delete or change | Object Lock in compliance mode, Backup Vault Lock, SCPs that deny the action, a separate log archive account |
| Must be able to prove / audit | CloudTrail (with log file validation), Config, Audit Manager evidence |
| As quickly as possible (incident) | Contain first: revoke sessions, isolate the instance, then investigate |
| Without traversing the internet | VPC endpoints, PrivateLink, Direct Connect |
Exam signal
When two options are both secure, the answer is usually the one that uses a managed control built for the job and applies it centrally, not a script that has to run in every account.
Deleting the evidence
In incident questions, options that terminate the instance, delete the compromised user or rotate every key "immediately" can destroy what you need to investigate. Contain first (deny, isolate, snapshot), then eradicate.
If your material is older
| Older material says | Use now |
|---|---|
| AWS SSO | IAM Identity Center |
| CloudFront Origin Access Identity (OAI) | Origin Access Control (OAC) |
| AWS WAF Classic | AWS WAF (the current version) |
| Amazon Kinesis Data Firehose | Amazon Data Firehose |
| Personal Health Dashboard | AWS Health Dashboard |
| DynamoDB Encryption Client | AWS Database Encryption SDK |
| AWS Security Finding Format (ASFF) as an exam topic | Open Cybersecurity Schema Framework (OCSF), used by Security Lake and Security Hub |
Least privilege is about what the principal can read as well as write. ReadOnlyAccess exposes every resource in the account, including data the auditors don't need. The Administrators option relies on a guardrail to take permissions away, and SCPs don't apply to the management account. The scoped policy grants only what the task requires.